Electronic Records
GST/HST memorandum 15-2
September 2026
This version replaces the June 2005 version, titled Computerized Records. This memorandum has been updated to include amendments to the Excise Tax Act regarding keeping books and records, including the information that may be specified for inspection by the Minister of National Revenue.
This memorandum explains the requirements for a person that keeps business records in electronic format to retain and make available such books and records, documents, and other information.
This memorandum does not provide detailed information about the digital-economy measures applicable to digital-economy businesses, including businesses that are registered or required to be registered under the simplified GST/HST registration regime of the digital-economy provisions of Subdivision E of Division II of the Excise Tax Act, and to platform operators and non-resident digital-economy businesses that are registered or required to be registered under the normal GST/HST registration regime. For more information, go to GST/HST for digital-economy businesses: Overview, or contact us at 1‑833‑585‑1463 (from Canada and the U.S.) or 613‑221‑3154 (from elsewhere – collect calls are accepted).
Table of Contents
General information
1. Electronic record-keeping refers to those electronic business systems that create, process, store, maintain, and provide access to a person's records. It includes but is not limited to custom and commercial accounting software, point-of-sale systems, and Internet-based electronic commerce. The rules in the Excise Tax Act (ETA) relating to record-keeping apply to all records generated by electronic business systems. It is the person's responsibility to keep, maintain, retain, and safeguard all of its electronic data files.
2. Under section 286, the following persons are required to maintain all records that are necessary to enable the determination of the person's liabilities and obligations under the GST/HST or the amount of any rebate or refund to which the person is entitled:
- every person who carries on a business or is engaged in a commercial activity in Canada
- every person who is required to file a GST/HST return
- every person who makes an application for a rebate or refund
3. The Minister of National Revenue (the Minister) may specify the form a record is to take and any information the record must contain. Unless otherwise authorized by the Minister, a record must be kept in Canada in English or in French.
4. For general information on record-keeping refer to GST/HST Memorandum 15-1, General Requirements for Books and Records.
Electronic record-keeping requirements
5. Under subsection 286(3.1), every person required to keep records, who does so electronically, is required to retain the records in an electronically readable format for a period of six years after the end of the year to which they relate. This means that a person must retain the electronic records even when a hard copy is available. Electronically readable format refers to information presented in a format supported by a system capable of producing accessible and usable copies.
6. The term electronic record is defined in the National Standard of Canada publication titled Electronic Records as Documentary Evidence (CAN/CGSB-72.34-2024) as an analogue or digital record that is carried by an electrical conductor and requires the use of electronic equipment to be intelligible by a person.
7. Accessible copy is not defined in the ETA but is generally understood to mean a copy of an electronic record in an electronically readable and usable format. An authorized person (for example, a Canada Revenue Agency [CRA] auditor or other officer) should be able to process the accessible copy on CRA equipment. A copy is usable if the electronic records can be processed and analysed with CRA software. The usable copy must be in a common data interchange format that is compatible with the CRA's software. Electronic files retained in an encrypted or proprietary backup format must be able to be restored at a later date to an accessible and usable state to meet the CRA's requirements.
8. Questions concerning the types of formats that are compatible with the CRA's software should be directed to the attention of the Computer Audit Specialist (CAS) at the nearest CRA Tax Services Office. Advice provided by the CAS must not be construed or viewed as an audit, inspection, or a ruling issued by the CRA. It is the person's responsibility to keep, maintain, retain, and safeguard its records.
9. Subsection 286(3.2) authorizes the Minister, on such terms and conditions as are acceptable to the Minister, to exempt a person or class of persons from the requirement in subsection 286(3.1) to retain their records in an electronically readable format.
Electronic commerce
10. Every person engaged in electronic commerce, which can be broadly defined as the delivery of information, products, services, or payments by telephone, computer, over the Internet, or by any other automated means, must retain electronic records that meet the requirements under subsection 286(3.1). The retained electronic records must, in combination with any other records such as the underlying contracts, price lists, and price changes, have an adequate level of detail to meet these legislative requirements.
Retention of electronic records
11. Every person using electronic business systems must ensure that sufficient detail is captured and produced to enable the GST/HST charged and remitted on taxable supplies of property and services as well as the GST/HST paid on purchases to be properly determined and verified.
12. Each person must ensure that its current and prior-period data files are, or have been, archived or backed up properly and adequately in order to meet its record-keeping obligations.
13. Each person that retains records by copying or backing up data to another medium must ensure that the method of retention complies with the medium manufacturer's suggested procedures, with particular attention given to the suggested shelf life of the medium. Information recorded on rewriteable media such as computer hard disks must be backed up on tape or on another suitable medium to avoid accidental loss, deletion, or erasure of the recorded information. The media containing the recorded information must be stored in an environment free from hazards that could affect electronic data such as magnetic fields, direct light, excessive moisture, and temperature extremes.
14. When backup copies of electronic files are being used as a method of record retention, procedures must be in place to ensure all of the following:
- the backed-up data files can be restored in a format that is accessible to and usable by the CRA
- the intended data are accurately and completely written to the medium used
- the backup procedure does not overwrite or destroy prior-period backup files or logs
- the medium is uniquely labelled in a readily identifiable manner
- the log identifies the records and data that have been recorded on the medium
- the log indicates how long the files or data on the medium are to be retained before they can be overwritten or discarded
- the name and version number of the software used to create the records are noted on the medium label and in the log
- the appropriate system software and operating system are available to restore the backup files to the original environment
- there is periodic testing of the backup records to verify that these records can be restored in an electronically readable format
Electronic records management and imaging
15. When original source documents and records are in an electronic format, they must be kept in an electronically readable format even if they have been transferred to another medium such as microfilm.
16. The National Standard of Canada CAN/CGSB-72.34-2024, Electronic Records as Documentary Evidence, available through the Canadian General Standards Board Catalogue, provides guidance on electronic record management policies, procedures, practices, and documentation that help ensure the reliability, integrity, authenticity, and legal validity of electronic records. Questions related to this standard should be directed to tpsgc.dgrgpongc-rgpbcgsb.pwgsc@tpsgc-pwgsc.gc.ca.
Managing retention and disposal of records
17. An acceptable imaging program requires all of the following:
- a person in authority in the organization has confirmed in writing that the program will be part of the usual and ordinary activity of the organization's business
- systems and procedures are established and documented
- an audit trail is created that contains sufficient and necessary audit data to provide evidence of the authenticity of the records made by the organization and of the integrity of any received records from the moment of receipt
- the imaging software maintains an index to permit the immediate location of any record, and the software inscribes the imaging date and the name of the person that does the imaging
- the images are of commercial quality, and are legible and readable when displayed on a computer screen or reproduced on paper
- a system of inspection and quality control is established to make sure that the procedures listed above are maintained
- after reasonable notification, equipment in good working order is available to view, or where feasible, to reproduce a hard copy of the image
18. Paper documents that have been imaged in accordance with the latest National Standard of Canada may be disposed of and their images kept as permanent records.
19. The person is responsible for ensuring that imaging is done in an acceptable manner when the imaging has been done by a third party.
Business system documentation
20. Documentation (whether in writing or any other form) that describes the operating and business systems must be maintained, retained, and provided to the CRA upon request.
21. Operating and business systems documentation should describe all of the following:
- the operation of the business system, including documentation relating to the data files
- the physical and system controls to prevent unauthorized alteration or loss of the records
- the creation and processing of transactions
- how standard reports are created
22. In addition to the normal business system documentation that is available, Internet-based transactions can generate additional information, either during transaction processing such as web logs, or as a result of security measures to preserve the authenticity and integrity of the resultant record such as electronic signatures. For persons with businesses operating on the Internet and using the services of an application service provider, this information must be obtained from that application service provider. The additional information and records form an important part of the audit trail for electronic commerce activity and, where relevant for GST/HST purposes, must be retained. The information produced must be retained for a period of six years from the end of the latest year to which they relate.
23. Documentation relating to data file retention and archiving includes such items as:
- procedures, including period retention, frequency of backups and archiving, and location of retained files
- file information such as file name, description, format, and record definition (record layout, data dictionary)
- description of storage media, hardware, and software used in the archiving process
24. Persons who outsource accounting or bookkeeping functions to third parties are required to provide this same documentation.
25. Documentation varies from system to system according to the complexity of the business systems and software. Where documentation is lacking for both custom and commercial business systems, it is good business practice to create the documentation where possible or contact the business system vendor to acquire the documentation.
Audit trails
26. An audit trail, which is the information that is required to re-create a sequence of events, must include sufficient detail to support summarized information. The electronic records must show an audit trail from the source document(s), whether paper or electronic, to the summarized financial accounts. In addition, the audit trail may include some links to other associated processes, documents, and events such as front-end systems (electronic commerce and point-of-sale), receipts, payments, and stock inventories, all of which may have their own system audit trails.
27. For Internet-based electronic commerce transactions, other records could be an important part of the audit trail, such as web logs and emails when used as part of the transaction (such as invoices and confirmations) or data generated by security measures (such as digital signatures). All transactions covered by an electronic data interchange trading partner agreement and the related electronic record(s), including functional acknowledgments, must be kept. It is the person's responsibility to ensure the reliability and readability of these records.
Converting from one format to another
28. Where electronically kept records are converted from one format to another, it is the person's responsibility to ensure that the converted records are reliable and readable. The conversion must not result in a loss, destruction, or alteration of information and data relevant to the determination of the GST/HST payable, collected, or withheld. This is particularly important with respect to Internet-based businesses that are dealing with third parties where documents and records relating to transactions are held or maintained by an application service provider.
29. Each person who keeps electronic records must also retain source documents. Source documents include items such as sales invoices, purchase invoices, cash register receipts, formal contracts, credit card receipts, delivery slips, deposit slips, work orders, dockets, cheques, bank statements, tax returns, and could also include emails and other general correspondence where relevant for GST/HST purposes. Paper or hardcopy records may be retained in microfiche, microfilm, or electronic record format in accordance with the policy outlined in paragraphs 15 to 19 of this memorandum. Where any of the aforementioned documents are created, transmitted, or received electronically, these documents constitute records and must be retained electronically.
Transaction integrity and security
Systems control
30. Every person who carries on a business with an electronic business system must put adequate controls in place to safeguard the accuracy, security, and integrity of the electronic records processed and kept in that system. These controls can include the following:
- access controls that ensure only authorized users can access the computer system and process data
- input and output controls that ensure the accuracy and security of information created, received, and transmitted
- processing controls that ensure the integrity of information processed by the system
- backup controls that ensure the retention of backup copies of electronic records, computer programs, system documentation, and the recovery of electronic records in the event of a system failure
- controls to ensure that there is no accidental or intentional editing or deletion of recorded or completed transactions
- journal entries adequately documenting any changes to recorded transactions, provided they include all of the following:
- the name of the person making the modifications
- the date of the change
- the previous transaction details
- the current transaction details
- the reason for the change or deletion
Changing electronic record-keeping systems
31. If changes to the operating and/or electronic business system are made, the capability to access and retrieve data must be preserved. The changes must not result in a loss, destruction, or alteration of information and data that must be retained under subsection 286(1). Adequate documentation must be retained to preserve an accurate chronological record of the changes, including any changes to software systems and the format of the files. This documentation must be made available, upon request, to the CRA.
32. Before implementing a new business system, a person must ensure all of the following:
- sufficient detail will be captured and produced to enable proper determination and verification of the GST/HST charged and remitted on taxable supplies of property and services as well as the GST/HST paid on purchases
- the audit trail of each transaction will be preserved to allow an authorized person to verify the accuracy of the GST/HST charged and remitted on taxable supplies of property and services as well as the GST/HST paid on purchases by the registrant
- adequate internal controls will be incorporated into the system so that all transactions are being recorded accurately and completely
- the system will verify transaction integrity and security
- the system will capture and save in a readable format all information required by the CRA
- the authorized person will have access to all information produced by the system and required by the CRA
- adequate backup and restore procedures will be in place to safeguard information required by the CRA
- the system will continue to offer the capacity to export the required information into a commonly used non-proprietary format
Commercial accounting packages
33. A person who uses commercial or customized software to keep books and records electronically is responsible to keep adequate electronic records despite deficiencies in the software. In cases where the software backup procedures are deficient, additional specific backup procedures must be in place to retain adequate electronic records. Documentation must be kept at a level of detail that will describe the data entry procedures, reports produced, and any features that alter standard reports or create new reports.
Third-party service providers
34. Every person who keeps records electronically remains responsible for record-keeping, readability, retention, and access to records where the person contracts out the record-keeping function to a third party such as a bookkeeper, accountant, Internet transaction manager, application service provider, cloud storage provider, or Internet service provider, through a time share, service bureau, or other such arrangement. The person must ensure that these requirements continue to be met in the event of third-party changes such as software or hardware conversions and upgrades, bankruptcy, or migration to or from a third party. The person is responsible for keeping the records and for providing access to authorized persons.
Working papers
35. Books and records may also be in the form of supporting documents such as an accountant's working papers, whether in writing or any other form, which assist in the determination of the person's GST/HST obligations and entitlements.
36. The person is responsible for ensuring that all electronic records are retained for the period of time specified by the ETA, and that the required data in an electronically readable format is available to provide to an authorized person when requested. A good practice is to have the third-party service provider provide the person with an acceptable copy of the information required by the CRA in an electronically readable format.
Inspections, audits and examinations
Inspections
37. In general, section 288 provides that a person authorized by the Minister may inspect, audit, or examine relevant documents, property, or processes of a person and, at all reasonable times, enter any premises or place of business and require persons therein to provide reasonable assistance and answer all proper questions. Such examinations include the audit of electronic records and, to comply with providing reasonable assistance, registrants must allow the authorized person access to their electronic records.
38. For more information on the application of section 288, refer to GST/HST Memorandum 15-1.
Business systems evaluations
39. The CRA may undertake a review of the business systems to understand the flow of information and identify electronic data files that are required. These reviews are undertaken to provide the CRA with an overview of the business system, including details related to the flow of information through the business system and subsystems. As part of providing reasonable assistance, registrants must provide, upon request from an authorized person, all information regarding their business systems.